Short Name |
HTTP:OVERFLOW:EPOLICY-OF |
|---|---|
Severity |
Critical |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
ePolicy McAfee Orchestrator Overflow Pilot |
Release Date |
2006/11/20 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+ |
This signature detect attempts to exploit a known vulnerability against McAfee ePolicy Orchestrator / Protection Pilot. Attackers can send an overly long source parameter in an http request that can result in gaining complete control of the target system.
The HTTP server component of McAfee ePolicy Orchestrator and ProtectionPilot is prone to a remote stack-based buffer-overflow vulnerability that can lead to complete system compromise. This issue arises because the application fails to perform boundary checks before copying user-supplied data into sensitive process buffers. A successful attack may result in arbitrary code execution with SYSTEM privileges, leading to a full compromise. McAfee ePolicy Orchestrator 3.5.0 patch 5 and prior versions as well as ProtectionPilot 1.1.1 patch 2 and prior versions are vulnerable to this issue.